← All industries
Insurance · Industries

IT & Microsoft cloud for insurance

Regulated data protection, secure communications and resilient IT for insurers and brokers.

Overview

Insurance

In short: FCA operational resilience, premium diversion, and the archive a broker is expected to be able to produce. Work from the questionnaire your insurers and network partners already send you: it is the clearest statement you will get of what you are being judged on.

Insurers and brokers hold exactly the personal and financial data attackers want most, and sit under exactly the regulatory scrutiny that punishes getting it wrong, from the FCA above and the ICO alongside.

The challenge

Insurance is one of the most heavily regulated sectors an SME can operate in. Brokers and insurers process personal and often special-category data at volume, they handle client money, and they run on email, quotes, claims correspondence, renewals and insurer communication, which makes them a standing target for business email compromise and premium-diversion fraud. The FCA's operational resilience rules expect regulated firms to identify their important business services, set impact tolerances and be able to keep those services running through disruption, including cyber incidents, and to evidence it. Consumer Duty raises the bar again on treating customers fairly, which in practice depends on systems being available and communications being accurate and retrievable. And the ICO expects appropriate technical and organisational measures around all that personal data. Security, compliance, retrievable records and genuine continuity all have to hold at the same time, and be demonstrable when someone asks.

What we would do

Work from the questionnaire your insurers and network partners already send you. It is the clearest statement of what you will be judged on, and premium diversion through business email compromise is the loss the whole sector is actually exposed to.

  • If FCA operational resilience is the driver, the important work is evidencing recovery rather than adding controls: what you would do, in what order, and how you would prove it afterwards.
  • If archiving is the gap, treat it separately from backup. They are different jobs and a product that is good at one is usually poor at the other.

When we are not the answer: If you already hold Cyber Essentials Plus, archive independently and test your recovery, you are ahead of most of the sector and do not need a review. We would rather say that than sell you one.

How we help

What we do for insurance

Layered cyber security (Managed Firewall, EDR, XDR) with 24/7 monitoring, mapped to the important business services your resilience plan depends on
Advanced email security and impersonation protection against BEC, phishing and premium-diversion fraud
Compliant, searchable, independent email archiving and retention so client and insurer communications are retrievable for the regulator, complaints and DSARs
Cyber Essentials and Cyber Essentials Plus certification
Operational resilience you can evidence: monitored, tested backup, disaster recovery and defined recovery times against your impact tolerances
Secure, Intune-managed Microsoft 365 and devices for office and hybrid teams, with identity locked down by MFA and Conditional Access

What does FCA operational resilience mean for a broker's IT?

It means naming your important business services, deciding how much disruption each can tolerate before it causes intolerable harm, and being able to show you can stay inside that tolerance.

The shift in thinking is away from whether systems are backed up and towards whether the service a client depends on keeps working, which is a harder question and a more useful one.

Naming the few services that matter, and why an untested impact tolerance is only an assertion

For a broker that usually means being specific about a handful of services rather than the IT estate as a whole. Placing cover, handling a claim notification, taking a premium payment, and giving clients access to their documents each have different tolerances. A claims line that is unavailable for a day during a weather event is a materially different problem from a document portal being slow, and treating them identically produces a plan that is both expensive and imprecise.

The evidence part is what most firms underestimate. An impact tolerance you have never tested is an assertion. Testing it means actually rehearsing a scenario, recording how long recovery took, and being honest when the answer exceeds the tolerance you set, then either improving the recovery or revising the tolerance for a defensible reason. Third parties are in scope too, so a software house or insurer platform your service depends on is part of the picture, not an excuse outside it.

How do you stop premium diversion and business email compromise?

By assuming the attacker will get a real mailbox rather than forge one, because increasingly that is what happens.

Insurance intermediaries handle client money moving between parties on a predictable rhythm, and that combination, large payments plus a known process plus multiple parties in the chain, is exactly what business email compromise targets. The attacker's goal is to sit inside a genuine conversation and change where money goes.

The technical defences that detect a takeover, and the payment rule that prevents the loss

The technical defences that matter most are the ones that prevent mailbox takeover and detect it quickly: multi-factor authentication without exceptions, conditional access that questions sign-ins that do not fit the normal pattern, and alerting on the tell-tale signs of a compromised account, particularly inbox rules that quietly move or delete messages so the real owner never sees the thread the attacker is running. Anti-impersonation controls then catch the lookalike-domain variant, where the attacker cannot get into a mailbox and registers something one character different instead.

The process defence is a rule about payment changes: bank details are never amended on the strength of an email, and any change is verified by phone to a number already on file. It is unglamorous and it is what actually stops the loss.

Why does email archiving matter more in insurance than most sectors?

Because the email frequently is the record. What was disclosed, what was recommended, what the client was told about an exclusion, when a claim was first notified: much of that lives in correspondence rather than in a system designed to hold it. When a complaint reaches the Financial Ombudsman Service years later, or a regulator asks, or a subject access request arrives, the ability to retrieve a complete and unaltered thread is the whole case.

Why a mailbox is not an archive, and why search quality matters as much as retention

Mailboxes alone are not a reliable archive. People delete things, leavers' mailboxes get removed, retention gets applied inconsistently, and a compromised account can have its contents altered. An independent archive captures messages as they are sent and received, keeps them tamper-evident for a defined retention period, and stays searchable regardless of what has happened to the original mailbox since.

Search quality matters as much as retention. An archive that technically holds seven years of mail but takes days to produce a specific thread has not solved the problem it was bought for, so the practical test is how quickly you can produce every message relating to one client across the full period.

What do insurers and network partners ask brokers about their own security?

The same questions brokers ask their commercial clients, which tends to be the uncomfortable part.

Insurer panels, networks and larger commercial clients increasingly run due diligence on intermediaries, and the questionnaires cover access control, multi-factor authentication, device management, patching, backup and testing, incident response, and how client data is handled through the chain.

How much Cyber Essentials answers on its own, and the process questions left over

Cyber Essentials, or Cyber Essentials Plus where a partner specifies it, answers a large share of this in a form the other side already recognises. That is its practical value here: rather than negotiating over bespoke evidence, you point to an externally assessed baseline. Where a partner asks specifically for the audited version, self-assessment will not satisfy them, so it is worth reading the requirement carefully before certifying.

The remaining questions usually concern process rather than technology, and they are the ones worth preparing in advance: who has access to client data and how that is reviewed, what happens on the day someone leaves, how an incident would be detected and who would be told, and within what timeframe. Firms that have written these down once answer consistently and quickly; firms that have not tend to answer differently each time, which invites more scrutiny rather than less.

What should a broker do in the first hour of a suspected email compromise?

Contain the account before investigating it, because every minute a compromised mailbox stays reachable is a minute an attacker can use it.

That means resetting the password and, critically, revoking active sessions, since a password reset on its own does not end a session an attacker already holds. This is the step most often missed, and it is why some firms reset a password and find the intruder still active afterwards.

Finding what was done rather than only what was read, who to warn, and the time-bound obligations

Then find out what was done rather than only what was read. Check for inbox rules the user did not create, particularly ones that forward, move or delete messages, because those are how an attacker keeps a conversation hidden from its real owner. Check for forwarding at the mailbox level, added devices or authentication methods, and any changes to trusted sign-in settings. Removing the attacker's access without removing their persistence means they return.

In parallel, warn the people at risk. If the account handles premium or claims payments, tell clients and counterparties not to act on payment instructions from that mailbox until told otherwise, using a channel other than the compromised email. Money moved during an incident is very difficult to recover, and the window for a bank to intervene is short.

Then handle the obligations, which for a regulated firm are real and time-bound. Assess whether personal data was accessible, since that drives whether the ICO must be notified within 72 hours, consider your FCA reporting obligations, and involve your cyber insurer early, because policies frequently require notification before you engage anyone to help. Deciding all of this during the incident is how firms miss deadlines, which is the argument for having the runbook written and the numbers to hand beforehand.

Frequently asked

Questions we hear a lot

How do you support FCA operational resilience requirements?

We provide the technical foundations that sit under your resilience plan: layered security and monitoring on the systems that carry your important business services, tested backup and disaster recovery with defined, evidenced recovery times you can hold against your impact tolerances, and clear documentation. You own the business-service mapping and the tolerances; we make sure the IT behind them can actually take a hit and keep running, and that you can prove it.

How do you defend against business email compromise and premium diversion?

With advanced anti-phishing and impersonation protection in front of mailboxes, correctly configured SPF, DKIM and DMARC so your domain can't be spoofed, MFA and Conditional Access on identity, and staff awareness. We also put process controls around changes to bank and payment details, so a convincing fake request to redirect a premium or claim payment is far less likely to land or be acted on.

Can you keep a compliant, retrievable record of client communications?

Yes. Independent, tamper-proof email archiving keeps a complete, searchable record of every message for as long as your retention obligations require, held separately from the live mailbox so it survives deletion or a compromised account. That makes responding to a complaint, an FCA request or a data subject access request a search rather than a scramble.

We're a broker handling special-category data. Are we covered for GDPR too?

The same controls do a lot of the work. Encryption, MFA, least-privilege access, device compliance, data loss prevention and tested backup are exactly the 'appropriate technical measures' UK GDPR expects around personal and special-category data, and archiving supports data subject access requests. We put those measures in place and help you evidence them alongside your FCA obligations.

Reading for insurance

Comparison guides

Free resources

Relevant client work

Our case studies are anonymised at our clients' request, so they name no sector. These are matched to the problems above rather than to the industry.

IT support for insurance is delivered UK-wide from our office in Brough, East Yorkshire, with on-site support across the county where it helps. We work with businesses in Leeds, York, Hull, Sheffield, Barnsley and Halifax and 6 more Yorkshire towns and cities, and remotely with clients right across the UK.

Ready to talk about your insurance IT?

Every engagement starts with a free assessment. No pressure, no cost, just a clear view of what's possible.